What the vulnerability does
01Description
Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue affects Squeeze: from n/a through <= 1.7.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
What the vulnerability does
Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue affects Squeeze: from n/a through <= 1.7.7.
Explanation of Vulnerability in Simple Terms
Squeeze versions up to 1.7.7 contain a flaw that allows an authenticated attacker to access sensitive information across the application scope. The vulnerability requires low-level privileges and network access but no user interaction. The exact nature of the information disclosure is unclear due to incomplete CWE classification. Update to version 1.7.8 or later.
What an attacker can do
Read sensitive information from the application that extends beyond their normal access scope.
Potential impact on your site
Users' sensitive data may be exposed to other authenticated users with low privileges.
Conditions required to exploit
Attacker must have a low-privilege account and network access to the application.
Key dates
External resources
Related vulnerabilities